Feeds

Canada's privacy chief hails Microsoft's Seven Laws of Identity

On surviving the identity Big Bang

Secure remote control for conventional and virtual desktops

The Information and Privacy Commissioner of Ontario has published a plan for automated internet privacy that is backed by Microsoft. Dr Ann Cavoukian has called for programmers to embed privacy capabilities in software.

A Microsoft-led project to create an "identity layer" for the internet created Seven Laws of Identity, which Cavoukian has used as the basis for a paper calling for the laws to be embedded in software. The aim of the project is to help computer users to manage their own identity online.

"Just as the internet saw explosive growth as it sprang from the connection of different proprietary networks, an 'identity big bang' is expected to happen once an open, non-proprietary and universal method to connect identity systems and ensure user privacy is developed in accordance with privacy principles," said Cavoukian.

"Microsoft started a global privacy momentum. Already, there is a long and growing list of companies and individuals who now endorse the Seven Laws of Identity and are working towards developing identity systems that conform to them," she said.

Cavoukian argues that the latest generation of internet services, commonly called Web 2.0 and depending in many cases on personalisation, will create a demand for more information about users' identities. Users will need to know whether they can trust a site before handing over information, and the Seven Laws are designed to help users make that decision, said Cavoukian's office.

Microsoft has published its own guidelines on embedding privacy into software. "Privacy concerns are easy to understand in principle, but challenging to address in practice, particularly in the development of software," said Peter Cullen, chief privacy strategist at Microsoft. "Similar guidelines have helped Microsoft's developers better understand and address privacy issues, and we hope that by releasing a public version we can promote an ongoing industry dialogue on protecting privacy through consistent development practices."

The proposals for embedded privacy settings is not unlike the Platform for Privacy Preferences (P3P), a World Wide Web Consortium-developed automatic reader and sender of information about a website's privacy policies. It was launched in 2002.

Couvoukian said that another aim of the Seven Laws is to help users cut down on the degree to which data is shared and centralised.

"In the real world when we present a library card, for example, to check out a book, and present our passport to cross a national border we don’t expect these to be linked together," she said. "Nor is the access card we use to enter our office the same as the transit pass we use to board a bus. In the physical world, different transactions require different identity credentials, but they need not be linked together. It should be no different in the online environment."

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Related links

Dr Cavoukian's white paper (24-page / 271KB PDF)
Microsoft's paper on The Laws of Identity

Beginner's guide to SSL certificates

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?